<html>
<head><meta charset="utf-8"><title>Newly released CVEs · t-release · Zulip Chat Archive</title></head>
<h2>Stream: <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/index.html">t-release</a></h2>
<h3>Topic: <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html">Newly released CVEs</a></h3>

<hr>

<base href="https://rust-lang.zulipchat.com">

<head><link href="https://rust-lang.github.io/zulip_archive/style.css" rel="stylesheet"></head>

<a name="234105813"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234105813" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Dirkjan Ochtman <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234105813">(Apr 12 2021 at 05:39)</a>:</h4>
<p>I just saw a whole bunch of Rust std CVEs pop up, including some going on up to 1.52.0</p>



<a name="234105825"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234105825" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Dirkjan Ochtman <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234105825">(Apr 12 2021 at 05:39)</a>:</h4>
<p><a href="https://bugs.gentoo.org/show_bug.cgi?id=782367">https://bugs.gentoo.org/show_bug.cgi?id=782367</a></p>



<a name="234105837"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234105837" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Dirkjan Ochtman <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234105837">(Apr 12 2021 at 05:39)</a>:</h4>
<p>Is a new release forthcoming? If not, should there be a quick blog post discussing these?</p>



<a name="234110508"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234110508" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Sebastien Marie (semarie) <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234110508">(Apr 12 2021 at 06:43)</a>:</h4>
<p>I read "in Rust <em>before</em> 1.52.0". It should be interpreted as "1.52.0 is not affected by it", isn't it ?</p>



<a name="234123319"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234123319" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Sebastien Marie (semarie) <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234123319">(Apr 12 2021 at 08:42)</a>:</h4>
<p>but at current time, stable channel is 1.51.0.</p>



<a name="234128465"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234128465" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Pietro Albini <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234128465">(Apr 12 2021 at 09:27)</a>:</h4>
<p>huh, we weren't the ones requesting those CVEs</p>



<a name="234128491"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234128491" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Pietro Albini <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234128491">(Apr 12 2021 at 09:27)</a>:</h4>
<p>looking at samples those seem to be "normal" unsoundness bugs someone requested a CVE for</p>



<a name="234139869"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234139869" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> Dirkjan Ochtman <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234139869">(Apr 12 2021 at 11:09)</a>:</h4>
<p><span class="user-mention" data-user-id="299750">@Sebastien Marie (semarie)</span> that's why I was wondering if a 1.51.1 release would be forthcoming</p>



<a name="234141019"></a>
<h4><a href="https://rust-lang.zulipchat.com#narrow/stream/241545-t-release/topic/Newly%20released%20CVEs/near/234141019" class="zl"><img src="https://rust-lang.github.io/zulip_archive/assets/img/zulip.svg" alt="view this post on Zulip" style="width:20px;height:20px;"></a> DPC <a href="https://rust-lang.github.io/zulip_archive/stream/241545-t-release/topic/Newly.20released.20CVEs.html#234141019">(Apr 12 2021 at 11:21)</a>:</h4>
<p>posted it in <a class="stream" data-stream-id="146229" href="/#narrow/stream/146229-wg-secure-code">#wg-secure-code</a> : <a href="#narrow/stream/146229-wg-secure-code/topic/cves.20in.20rust.20as.20per.20gentoo.20thread/">https://rust-lang.zulipchat.com/#narrow/stream/146229-wg-secure-code/topic/cves.20in.20rust.20as.20per.20gentoo.20thread/</a></p>



<hr><p>Last updated: Aug 07 2021 at 22:04 UTC</p>
</html>